just thinking out loud, but aren't their tools that convert checkpoint and what not to IPTables format? if so can you take those and put them in the config files for astaro?
Checkpoint: yes; good you point that out! Whatnot: spotty.
Your idea is a good one: A parser that abstracts/reverse compile iptables and a set of Network Definitions back into simpler /etc/wfe/conf/packetdata rules. The people who have their head in the iptables rules generation at Astaro will know if it's workable. You would have to have it such that the mappings from the simple rules to the complex (iptables) ones are fairly unique...